CMMC Level 1 · ChecklistSEC / CHK15 / 59

CMMC Level 1 · Reference

The CMMC Level 1 Checklist

All 15 requirements and 59 assessment objectives to work through, grouped by domain. Print this page, or follow any item through to its official text and source.

How to Use This

First find where Federal Contract Information lives in your systems. Those systems are your scope. Then work each requirement below and record a determination for it. Scope is a boundary decision you make, and each determination is yours to make and record.

Each assessment objective is determined MET, NOT MET, or N/A, and each requirement rolls up to MET or NOT MET. There is no numeric score at Level 1, and no plan of action and milestones. Every requirement must be MET, or N/A where it does not apply, before you affirm.

Access Control

AC · 19 objectives

Identification and Authentication

IA · 6 objectives

Media Protection

MP · 2 objectives

Physical Protection

PE · 10 objectives

System and Communications Protection

SC · 10 objectives

System and Information Integrity

SI · 12 objectives

Build the Record Behind This

AssessrLog is a working reference you do not rebuild in a spreadsheet every year. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and keep the record in one place for the six-year retention. The determination is always yours to make.